
CVE-2026-66066
PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Monkey-patch gem for CVE-2020-5267 that fixes a timing-based vulnerability in ActionDispatch for Rails 4 and 3, providing a tested security backport…

Exploit for Rails CVE-2019-5420 targeting insecure session key derivation in development mode, enabling remote code execution via crafted requests.

Dockerized exploit environment for CVE-2019-5420 (Ruby on Rails Active Storage) enabling remote code execution. Designed for educational testing and…

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Proof-of-concept exploit for CVE-2022-32224: Rails ActiveRecord serialized column RCE. Demonstrates YAML deserialization leading to arbitrary class…

Proof-of-concept exploit for CVE-2019-5420 (Rails cookie deserialization) with argparse-based cookie modification, designed for PentesterLab practice.

Proof-of-concept exploit for CVE-2019-5420, a remote code execution vulnerability in Ruby on Rails, designed for educational purposes.

Test cases for broken MIME and tools to generate and process these

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

Proof-of-concept exploit for CVE-2014-0130, a Rails directory traversal vulnerability. Demonstrates path traversal payload and references HackerOne…

Python exploit for CVE-2020-8165 targeting Rails MemCacheStore and RedisCacheStore. Enables remote command execution via user-provided object…

Automated exploit script for CVE-2020-8165 targeting Rails applications, enabling remote code execution via crafted payloads.

Proof-of-concept exploit for CVE-2019-5420 targeting Rails development mode secret token disclosure to escalate privileges via cookie manipulation.

Step-by-step exploit for Ruby on Rails CVE-2019-5420 RCE via insecure Marshal deserialization, with payload generation and reverse shell capture.

Proof-of-concept exploit for CVE-2016-0752, a Rails dynamic render remote code execution vulnerability, with setup instructions and reference to a…

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156